I am running a basic search and wanting to perform a reverse DNS lookup.
index=*proxy src_ip="10.x.x.x" | lookup dnslookup clientip as src_ip OUTPUT clienthost as Hostname
| table Hostname
The search is not returning any fields named Hostname. What am I missing? Is there a way to validate the external lookup python script is working?
external_cmd = external_lookup.py clienthost clientip
fields_list = clienthost,clientip